Ryuk ransomware member sentenced to 24 months in prison

A notorious figure in the world of cybercrime has been brought to justice. Karen Serobovich Vardanyan, a 35-year-old Armenian man known online as “Maneeken” or “Karl Lagerfeld,” was sentenced to 24 months in prison and three years of supervised release for his role in Ryuk ransomware attacks that targeted U.S. companies between March 2019 and June 2020.

Vardanyan’s crimes were part of a larger scheme by the Ryuk ransomware group, which operated as a “ransomware-as-a-service” (RaaS) operation. This means that Vardanyan and his accomplices essentially acted as middlemen, providing malware to other hackers who carried out the attacks in exchange for a share of the profits.

The Ryuk gang was notorious for its brazen attacks on healthcare organizations during the COVID-19 pandemic, hacking around 20 victims every week and collecting more than $150 million in ransoms. The group’s shutdown in mid-2020 led to a surge in activity from other ransomware gangs, including Conti, which eventually disbanded in 2022 after its internal chats and source code were leaked.

Vardanyan’s case is significant because it highlights the global scope of cybercrime operations. He was extradited from Ukraine after being arrested in April 2025, and pleaded guilty to hacking into the networks of multiple U.S. organizations using Ryuk ransomware. In one notable attack, Vardanyan and his accomplices breached a Michigan company that paid 200 BTC (worth over $1.1 million at the time).

The impact of these attacks was devastating for the victims. Not only did they lose significant sums in ransoms, but they also faced lengthy downtimes while their systems were restored. The U.S. Department of Justice described Vardanyan’s crimes as “serious” and noted that he and his co-conspirators received approximately 1,610 bitcoins in ransom payments, valued at over $15 million.

The sentencing of Vardanyan sends a clear message to cybercriminals: law enforcement agencies are actively working to disrupt and dismantle these operations. However, it also underscores the need for organizations to remain vigilant against these threats. With the rise of RaaS operations like Ryuk and Conti, companies must prioritize their cybersecurity measures and stay informed about emerging threats.

For individuals and businesses alike, this case serves as a reminder to take proactive steps in protecting themselves from ransomware attacks. This includes keeping software up-to-date, using robust antivirus solutions, and implementing regular backups of critical data. By being prepared for the worst, organizations can minimize their risk exposure and avoid falling victim to these devastating attacks.


Source: Bleeping Computer — 2026-09-23